Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

401–410 of 466 posts

Re: I found a vulnerability. they found a lawyer

#401
post #349

Earlier quoted context omitted.

>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?

Portugal, Germany, Canada, Switzerland are the ones I am aware of. Software Engineering degrees are certified by the Engineering Order, universities cannot call themselves that just because they feel like it, and any kind of legal binding documents when notarised required the professional validity.

First of all, hardly anyone cares (default email signatures etc.pp even if the people don't want that - but you said legally bindign, and I think that just usually never happens.).

And second, at least in Germany it's also somewhat of a bullshit situation that 80% of the people who do a "normal" Computer Science degree don't have that (Diplom-Informatiker/M.Sc), but the 20% who happen to study at a certain uni in a certain degree (that is mostly related, but not the default Computer Science/Software Engineering one) are/were getting their "Diplom-Ingenieur".

Re: I found a vulnerability. they found a lawyer

#402

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

> running a script which tries every password This isn't directly applicable to your point, but I need to correct this. They weren't guessing tons of passwords, they were were trying one password on a large number of accounts.

Correct you are.

Re: I found a vulnerability. they found a lawyer

#403
post #401
post #349

Earlier quoted context omitted.

Portugal, Germany, Canada, Switzerland are the ones I am aware of. Software Engineering degrees are certified by the Engineering Order, universities cannot call themselves that just because they feel like it, and any kind of legal binding documents when notarised required the professional validity.

First of all, hardly anyone cares (default email signatures etc.pp even if the people don't want that - but you said legally bindign, and I think that just usually never happens.). And second, at least in Germany it's also somewhat of a bullshit situation that 80% of the people who do a "normal" Computer Science degree don't have that (Diplom-Informatiker/M.Sc), but the 20% who happen to study at a certain uni in a c…

Thanks to Hamburg you can call yourself an Ingenieur with a bachelor of science (German source: https://www.bit01.de/blog/informatiker-ingenieur-titel/ ... although it's 5 years old now. Should still be valid.)

Re: I found a vulnerability. they found a lawyer

#404

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

Theoretically, the easiest way is to use a sub address (more commonly/colloquially known as email aliases or plus addresses, they're described in RFC 5233). You should be able to add a separator character (usually a plus, sometimes other characters instead/in addition) and arbitrary text to your email address, i.e. "myemail+somecompany@example.com" should route to "myemail@example.com"

In practice, this works about 95-99% of the time. Some websites will refuse the + as an invalid special character, and the worst of the worst will silently strip it before persisting it, and may or may not strip it when you input your email another time (such as when you're logging in or recovering your password).

I also suspect spammers strip out subaddresses frequently, very little of the spam I receive includes the subaddress.

So the only 100% reliable way is to use your own domain, but you don't need to run your own custom mail server

Re: I found a vulnerability. they found a lawyer

#405

Earlier quoted context omitted.

You'd be surprised how many SE's would love for this to happen. The biggest reason, as you said, being able to push back. Having worked in low-level embedded systems that could be considered "system critical", it's a horrible feeling knowing what's in that code and having no actual recourse other than quitting (which I have done on few occasions because I did not want to be tied to that disaster waiting to happen). I…

The problem with software is that it's all so, so decentralized. If you're building a bridge in South Dakota, there's somebody in South Dakota building that bridge. That person has to follow South Dakota laws, and those laws can require whatever South Dakota regulators want, including sign-offs by professional engineers. If you're a South Dakota resident signing up for a web portal, the company may have no knowledge…

Bridges are only built on-site. They're designed and engineered elsewhere, frequently overseas.

Re: I found a vulnerability. they found a lawyer

#407
post #238

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

Another missing link is here is the stock price relationship to security vulnerability history of the corporation. Somehow, I don't know how, but somehow stock prices should reflect the corporation's social responsibility posture, part of which is information security obviously.

They do. No one actually cares is the current value. Insurance companies are barely starting to care.

Re: I found a vulnerability. they found a lawyer

#408

If this was in Costa Rica the appropiate way was to contact PRODHAB about the leak of personal information and Costa Rica CSIRT ( csirt@micitt.go.cr ). Here all databases with personal information must be registered there and data must be secure.

> If this was in Costa Rica the appropiate way was to contact PRODHAB about the leak of personal information and Costa Rica CSIRT ( csirt@micitt.go.cr ). They did. It's in the article. Search for 'CSIRT'. It's one of the key points of the story.

They reached Malta CSIRT. Costa Rica and Malta are totally different countries.

Re: I found a vulnerability. they found a lawyer

#409
post #181

Maintaining Cybersecurity Insurance is a big deal in the US, I don't know about Europe. So vulnerability disclosure is problematic for data controllers because it threatens their insurance and premiums. Today much of enterprise security is attestation based and vulnerability disclosure potentially exposes companies to insurance fraud. If they stated that they maintained certain levels of security, and a disclosure de…

It's not generally good financial advice to pay the overhead of an insurance company for costs you can easily pay yourself (also things like phone insurance, appliance warranty extensions, etc. won't make your device last longer and the insurer knows better than you what premium covers the average repair costs plus a profit margin). If you have a decent understanding of where the line is between vulnerability disclos…

> It's not generally good financial advice to pay the overhead of an insurance company for costs you can easily pay yourself

For a lot of companies, a lawsuit would be the end of them even if it's not financial ruin. Often times the decision to purchase insurance isn't made by the CEO but rather by the board of directors.

Board directives are often why you see companies adopting or trending towards certain activities that don't necessarily make sense. They might be at the benefit of a member of the board or one of the other companies they chair.

Re: I found a vulnerability. they found a lawyer

#410
post #111

Maintaining Cybersecurity Insurance is a big deal in the US, I don't know about Europe. So vulnerability disclosure is problematic for data controllers because it threatens their insurance and premiums. Today much of enterprise security is attestation based and vulnerability disclosure potentially exposes companies to insurance fraud. If they stated that they maintained certain levels of security, and a disclosure de…

Heh, what insurance company you use should be public information, and bug finders should report to them.

I wonder what that might reveal. Often decisions are made at the direction of the board of directors. I have to imagine they would be opposed to such disclosures as it might shine poorly on them.
Post reply on HN